Reverse engineering ELRO HA51 wireless

Contents

What is it

It's a alarm system, used with wireless accessories.
We have a central and a remote control:

Setup

We opened the device, no internal alarm trigger's where used.
The system contains 2 board:

Logic board

433 receiver

We hooked up a logic analyzer on the 433 receiver board to "snif" the datastreams:
We opened the remote to change the dipswitches:

Results

After sniffing a few times this the result:
"Put alarm off" with all dips off:
"Put alarm off" with all dips on:
As you can see, the first pulse is always short, the next 8 pulses is the code of the system, dip "off" is a small pulse, a wide pulse is dip "on".
Also we have seen the last 4 pulses are used to control the system:
Wide=1
Small=0